Privacy Policy
Last updated: 3 September 2026
This page explains what personal data we collect when you reserve a spot for ANIJAM, why we collect it, and what rights you have over it. Plain language — no fine print.
Who is responsible for your data
The data controller is the ANIJAM team — an informal group of organisers, not a registered legal entity. For anything to do with your data, email [email protected].
We process data in line with the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) and Bulgaria’s Personal Data Protection Act.
What we collect
When you fill in the reservation form, we collect only:
- Name — as you type it, so we can find you on the door list.
- Email address — to send you a confirmation link and information about your reservation.
- Language (Bulgarian or English) — so we email you in the right one.
- A hashed form of your IP address — your IP address is never stored in the clear; we keep only an irreversible hash (SHA-256), used solely to limit abuse and spam.
- Your country, at the moment you submit — online reservations work from Bulgaria only, so when you send the form we check which country the request comes from. Cloudflare resolves this at the network level; the result is used immediately and never stored — neither the country nor your IP address in readable form.
- Reservation metadata — a random reservation code, status (pending / confirmed / waitlisted) and timestamps.
- A “checked in” flag — at the door we mark who arrived, so we know how many people are in the room.
We take no online payments — the door fee is paid in cash on site. We neither ask for nor store any other data.
Name and email are required — without them we can’t hold a spot for you or send you a confirmation. Everything else in the list above is generated by the system; you never type it.
Why we collect it, and our legal basis
- To create and manage your reservation, track capacity and email your confirmation — on the basis of Art. 6(1)(b) GDPR: the processing is necessary to carry out the reservation you asked for.
- To protect the form from bots and abuse (the IP hash, the bot check) — on the basis of our legitimate interest in protecting two things: the free places, so they can’t be taken en masse by automated requests at the expense of real guests, and the form itself, so it can’t be used to send unwanted email to other people’s addresses. Art. 6(1)(f) GDPR.
- To check which country the request comes from — on the basis of our legitimate interest in the limited number of free online places going to people who can actually attend in Sofia. The country is used at the moment of the request and is never stored. Art. 6(1)(f) GDPR.
We don’t use your data for advertising and we don’t sell it to anyone.
Who we share it with
Your data passes through a few service providers who process it only so the site can work:
- Cloudflare — hosts the site, the database (Cloudflare D1) where your reservation is stored, and the bot protection (Turnstile).
- Brevo — the service that sends the confirmation emails (it receives your name and email). Brevo is a French company and processes the data in the EU.
The site’s fonts are served from our own server, not from Google — opening a page makes no font request to any third party.
Beyond these providers we don’t share your data with third parties, unless required by law.
Within the team, the name list is visible only to the organisers, through a password-protected page. At the door we use that same list (on screen or printed) to check names off.
Transfers outside the EU
Cloudflare is a US-based company, so your data may be processed or stored outside the European Economic Area. That transfer relies on two of the safeguards the GDPR provides for: Cloudflare is certified under the EU–US Data Privacy Framework, and our agreement with them also incorporates the European Commission’s standard contractual clauses. Brevo is EU-based and processes the emails in the EU, and the fonts are now served from our own server — neither involves a transfer outside the EEA.
Cookies
We use no advertising or tracking cookies. Cloudflare’s bot check (Turnstile) may load a small technical element, needed only to confirm you’re human. The only thing the site writes to your browser is a sessionStorage flag noting that the intro animation has already played — no personal data, cleared when the tab closes.
How long we keep it
- Unconfirmed reservations expire 30 minutes after they’re submitted — the seat is freed immediately, and the record itself is deleted automatically shortly afterwards.
- Confirmed reservations are kept until the event and deleted within 30 days afterwards.
- If you cancel your reservation (via the link in the email), it is deleted immediately.
How we keep it safe
The site runs over HTTPS only. The confirmation and cancellation links contain a random token, of which the database holds nothing but an irreversible hash — anyone reading the database still can’t forge a working link. Your IP is stored as a hash too. The door list sits behind a password.
Age
The reservation form is for people aged 14 and over. If you’re younger, ask a parent or guardian to reserve for you, using their own email. The event itself is for all ages — this rule is only about filling in the form online.
Automated decisions
We don’t profile you and we make no automated decisions that have legal effects for you. The only automatic part is the ordering: if the room is full you join the waitlist in the order you signed up, and the system moves you up when someone frees a spot.
Your rights
Subject to the conditions set out in the GDPR, you have the right to request:
- access to the data we hold about you;
- correction of inaccurate data;
- erasure (the “right to be forgotten”);
- restriction of, or objection to, processing;
- data portability.
You can cancel your reservation at any time — most easily from the link in the email, or by emailing us at [email protected].
For more about the GDPR, visit cpdp.bg.
Changes to this policy
If we change how we handle data, we’ll update this page and the “last updated” date at the top.